This is a translation for your convenience. The German version is the legally binding one; where the two differ, the German text applies.
Privacy policy
As of 5 October 2026 · Legal framework: GDPR (Regulation (EU) 2016/679), BDSG and TDDDG.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is the person named in the legal notice. Contact for privacy matters: info@meisgaming.net.
No data protection officer has been appointed; given the nature and scale of the processing, none is required (Art. 37 GDPR).
2. Overview: what we process and why
purrr.chat is a self-hosted chat platform. We only process the data needed to register, run and secure the service. We use no advertising or analytics trackers, sell no data and pass nothing on to third parties unless the law requires us to.
3. What data we process
a) Account data
Username, email address, password (stored only as a cryptographic hash, never in plain text) and, optionally, display name, avatar and profile texts.
Legal basis: Art. 6(1)(b) GDPR (performance of the terms of use).
b) Content (messages and uploads)
Messages you send and files you upload are stored on the server until you delete them or your account is deleted; uploaded files are not removed automatically once they reach an age limit. Messages can be read on the server (no end-to-end encryption); transport is encrypted with TLS. When you delete a message, we keep a copy of it for 14 days so that moderation can review removals; after that it is deleted automatically.
Legal basis: Art. 6(1)(b) GDPR.
c) Voice and video chat
Audio and video are relayed in real time through our server (SFU) and are neither recorded nor stored. Your IP address is technically visible to the server in the process, not to other participants. For redundancy, voice runs across our own servers at two Hetzner locations; during maintenance an ongoing call can be handed over to the other machine automatically — also live only, with no recording.
Legal basis: Art. 6(1)(b) GDPR.
d) Technical server logs
Two kinds of logs arise for operational security and troubleshooting: web server access logs (IP address, time, requested address, where sent browser details) on the entry server, rotated after 14 days, and application logs of the containers (requests, app messages), which are size-capped (max. 3 × 10 MB per service) and deleted as they roll over.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working service).
e) Web push notifications
If you turn on notifications, we store your browser’s push subscription (endpoint URL and cryptographic keys). Delivery runs through the push service of your browser’s vendor (depending on the browser, e.g. Mozilla, Google or Apple; their servers may be outside the EU). You can turn push off again in the settings at any time.
Legal basis: Art. 6(1)(a) GDPR (consent, given by turning it on).
f) Bug reports
If you report a bug through the app, we store your text and technical details about your browser (version, window size, the view you were on) so we can reproduce the problem.
Legal basis: Art. 6(1)(f) GDPR.
g) Presence and rich presence
Whether you are online, which status (online/idle/do not disturb) applies and what kind of device you are on is shared with the members of the dens you are in. A voluntary activity entry (such as a running game or music) is detected locally on your device and only if you have turned the feature on in the settings; that entry is relayed to others live only and is not stored permanently on the server. What is stored permanently is only your chosen status and your own status text. You can also configure, per den or per contact, that others see you as offline (“hidden”).
Legal basis: Art. 6(1)(b) GDPR; for the voluntary activity additionally lit. a.
4. No cookies, no tracking
purrr.chat sets no cookies for advertising or analytics and uses no third-party analytics or advertising services. The login tokens needed to sign in are kept in your browser’s localStorage (technically necessary, no consent required, § 25(2) TDDDG). Fonts and all other resources are loaded from our own server — no requests go to third parties (such as Google Fonts or CDNs).
5. Hosting, backups and processors
To run the service we use providers that process data on our behalf and on our instructions (processing on behalf, Art. 28 GDPR). A data processing agreement is in place with each of them. We use no analytics, advertising or tracking services; the list below is complete.
| Provider | Purpose | Where processing takes place |
|---|---|---|
| Hetzner Online GmbH Industriestr. 25, 91710 Gunzenhausen, Germany | Server, database, file storage | Data centre in Falkenstein, Germany |
| Hetzner Online GmbH | Second location: running copy of the database (warm standby) and a second copy of uploaded files, for redundancy only | Data centre in Nuremberg, Germany |
| Hetzner Online GmbH | Another of our own servers; currently processes no purrr data (internal network only) | Data centre in Falkenstein, Germany |
| Hetzner Online GmbH (Storage Box) | Daily backup of the database and uploads | Falkenstein, Germany |
| Hetzner Online GmbH (Storage Box) | Backup of the server configuration; no messages, uploads or account data | Helsinki, Finland (EU) |
| STRATO AG Otto-Ostrowski-Str. 7, 10249 Berlin, Germany | Sending service emails (confirmation, password reset) | Germany |
Traffic between our own servers runs entirely through an encrypted internal network (WireGuard); database and file replication happen only there, never over the open internet.
When we host outside Germany, we only do so inside the EU or the EEA — under the same data protection law that applies here. That is why the configuration backup sits in Finland and not just anywhere: it is not a transfer to a third country within the meaning of Art. 44 et seq. GDPR, because Finland is an EU member state. Should that ever change, it will say so here first.
GIF search
GIF search uses the API of KLIPY (Kikliko, Inc., USA). What matters is how: your request does not go there from your device. Our server asks with its own access key and sends nothing but the search term — no identifier, no account data, not your IP address. You do not load the images from KLIPY either, but through our server (/files/proxy). In our assessment, no personal data is transferred to KLIPY this way.
Translation
Translation runs on a separate service on the same server (LibreTranslate, reachable only on the internal network). The text of a message does not leave our server for it.
Only if you choose to add your own DeepL API key in your settings are the texts you select for translation sent to DeepL — under your own contract with DeepL, at your own decision.
6. Transfers to third countries
The service itself runs entirely inside the EU. There is exactly one place where data can leave the EU, and it depends on you:
Push notifications. If you turn them on, delivery necessarily runs through your browser vendor’s push service (e.g. Mozilla, Google or Apple), whose servers may be in the USA. For US providers certified under the EU-U.S. Data Privacy Framework there is an adequacy decision of the European Commission (Art. 45 GDPR); otherwise the transfer is based on your explicit consent (Art. 49(1)(a) GDPR), which you give by turning push on and can withdraw in the settings at any time.
Without push notifications turned on, using purrr.chat involves no transfer to a third country.
7. Bots and third-party applications
purrr.chat has an open API that third parties can use to run bots and applications. That is intended — but it has a consequence you should know about.
If someone adds a bot to a den, that bot can see the content of the channels it was given access to, including your messages there. What a bot then does with that data is the responsibility of whoever runs the bot, not of purrr.chat — that person or company is a controller in their own right within the meaning of Art. 4(7) GDPR and needs their own legal basis and their own privacy policy. Our terms of use oblige bot operators to this, but we do not pass data on on their behalf and cannot monitor what they do.
In practice: in a den that is not yours, check which bots are members, just as you would on any other chat platform. Whoever manages a den decides which bots have access there.
8. Bridges to other platforms
A den can be connected to a server on another platform (currently Discord). If a channel is bridged this way, messages from that channel — content, display name and avatar — are sent to the other platform and stored there under its terms, in Discord’s case by Discord Netherlands BV or Discord Inc. (USA). In the other direction, messages from there arrive in the purrr channel.
That is decided by whoever manages the den, not by us. How to tell: mirrored messages from the other platform carry the webhook message label, and a bridged channel shows a Bridged note in its header as long as messages have crossed the bridge in the last 30 days. If you are unsure, ask the den’s moderators.
9. Recipients and disclosure
Your data is not sold. It is only passed on to the processors named above, in the cases described in sections 7 and 8, or where we are legally obliged to (e.g. information to law enforcement on a valid legal basis). Content you post in shared channels or dens is visible to the other members of those channels — that is the nature of a chat service.
10. Retention
- Account and content: until you delete it or the account is deleted.
- Web server access logs: 14 days.
- Moderation archive of deleted messages and edits: 14 days.
- Requested account erasure: a 14-day grace period until execution, cancellable at any time; the operational audit lines about the request remain afterwards.
- Push subscriptions: until you turn push off or the push endpoint becomes invalid.
- Backups: deleted data may still exist in backup copies for a limited period (up to 14 days) before they are overwritten in rotation.
A deletion takes effect in the live service immediately. That it reaches the backup copies only with their rotation is technically unavoidable and permitted under Art. 17(1) GDPR, as long as backups are never restored into the live service without applying the deletion again.
11. Confidentiality of communications
purrr.chat is a number-independent interpersonal telecommunications service. The content of your messages and the details of your communication are therefore protected by the secrecy of telecommunications (§ 3 TDDDG). We may only take note of them as far as running the service, its security or a legal obligation requires — for instance when handling a report about illegal content. Reading along for any other purpose does not happen, and everyone with administrative access is bound to this.
12. Your rights
Under the GDPR you have the right to:
- access the data stored about you (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure (Art. 17, “right to be forgotten”);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time, with effect for the future (Art. 7(3)).
An informal message to info@meisgaming.net is enough to exercise them. Many actions (changing your profile, deleting messages or your account) you can also take directly in the app.
Data export (Art. 15 and 20): In your account settings you can download your data as a machine-readable file: your profile and settings plus your most recent 10,000 messages with the metadata of their attachments (the files themselves you fetch through their usual links); anything the cap cut off is explicitly marked in the export. The export contains only your own data.
Account erasure (Art. 17): In the privacy settings you can request four things: deletion of your account, of all your messages in one den, of all your direct messages, or of everything. In the default mode your messages are anonymised (author removed, the content remains visible from an “unknown author”); with the switch set to “delete”, they are permanently removed. Every request waits out a 14-day grace period and can be cancelled at any time until then.
13. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular the one where you live. The authority responsible for the controller (Bavaria) is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
14. Minimum age
Using purrr.chat requires a minimum age of 16 (cf. Art. 8 GDPR, the German age of consent for this). We do not address children under 16 and do not knowingly process their data.
15. Data security
Passwords are stored only as hashes, and every connection is encrypted with TLS. Server access works exclusively via SSH with keys (no password logins), traffic between our own servers runs through an encrypted internal WireGuard network whose internal services are not reachable from the internet, login attempts are blocked automatically and the systems receive security updates automatically. The detailed description of our technical and organisational measures (Art. 32) is documented internally. Absolute security cannot be guaranteed for data transmitted over the internet.
16. Changes to this policy
We update this privacy policy when the service or the law changes. The current version is always available here; material changes are announced in the app.